Skip to main content

Processing of (personal) data by the entity in charge of the online application process

Thermoteknix Privacy Notice


1. Introduction

Thermoteknix respects your privacy and is committed to protecting your personal data. We process personal information in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018, and other applicable data protection laws.

This privacy notice explains how we collect, use, store and protect personal data relating to job applicants.

Thermoteknix is committed to handling personal data in a lawful, fair and transparent way and only processes information where it is necessary and proportionate.

It explains:

  • what personal data we collect
  • why we collect and use it
  • who we share it with
  • how long we keep it
  • how we keep it secure
  • your rights under data protection law

This notice applies to job applicants.


2. Who we are

Thermoteknix Systems Ltd is the data controller responsible for the personal data described in this notice.

Our registered office address is:

Tennyson House, Cambridge Business Park, Cambridge, Cambridgeshire, United Kingdom, CB4 0WZ

We are registered with the Information Commissioner (ICO) and our registration number is ZA153109.

Contact details:

For queries in relation to this notice and your personal data please contact:

The HR team on HR@thermoteknix.com or our Internal Data Protection Lead on dataprotection@thermoteknix.com


3. The types of personal data we process

During recruitment, we process personal data including:

  • name, title and contact details
  • date of birth and identification information
  • National Insurance number
  • employment history, qualifications and training records
  • recruitment information such as CVs, applications, interview notes and assessments

We only collect personal data that is necessary at each stage of the process. We do not collect special category data, such as health information or criminal record (DBS) details, during the initial recruitment stages.

If you are offered employment, we will need to carry out background checks and collect additional information to support your employment. These checks may feel intrusive; however, due to the nature of our work, including our contracts with certain clients and associated security and legal obligations, they are necessary and required.

More information about how we use this data can be found in our employee privacy notice.


4. Where your personal data comes from

We obtain data from:

  • applicants directly
  • recruitment agencies
  • referees
  • background screening providers
  • government bodies (e.g. right to work checks)
  • publicly available professional sources

We will only collect references from contacts you have provided. We will also inform you before carrying out any background screening checks.

Please note that where background checks are required for a role, if you choose not to participate, we may not be able to progress your application or offer employment.


5. Why we use your personal data

We use data to:

  • manage recruitment and selection
  • assess suitability for the role
  • verify identity and right to work


6. Lawful bases for processing

We rely on different legal grounds under data protection law to process your information, depending on the purpose:

  • Contract (pre-employment steps) – where we need information to assess your application and take steps towards offering you employment
  • Legal obligation – where we are required to process information to comply with the law, such as checking your right to work in the UK
  • Legitimate interests – where it is necessary for our recruitment processes and business operations, provided this does not override your rights
  • Consent (limited cases) – used only where appropriate, such as for equality monitoring information, which is entirely voluntary

Some types of information are considered more sensitive, such as health information and criminal record data. We only process this kind of information where it is necessary, and always in line with the Data Protection Act 2018 and appropriate safeguards.


7. Automated decision- making

Thermoteknix does not make employment decisions that are based solely on automated decision making where those decisions would have legal or similarly significant effects, unless permitted by law and subject to safeguards.

Important employment decisions are always reviewed and made by people.


8. Who we share personal data with

We share personal data only where necessary and lawful. This may include sharing information with:

  • internal departments and managers involved in the recruitment process
  • recruitment agencies acting on your or our behalf
  • referees you have provided
  • background screening or vetting providers where checks are required
  • government bodies such as HMRC or the Home Office (for example, for right to work checks)
  • regulators or law enforcement where we are legally required to do so
  • screening or vetting providers
  • professional advisers such as legal advisers, auditors or HR consultants
  • IT system providers who support our systems

Appropriate contractual safeguards are in place where third parties process data on our behalf. We ensure that access to your information is proportionate and lawful.


9. International transfers

Whilst we do not transfer data outside of the UK routinely, some of our service providers may do so.

Where this happens, we ensure appropriate safeguards are in place such as:

  • countries recognised by the UK as providing adequate protection
  • approved international data transfer agreements and transfer risk assessments
  • appropriate contractual safeguards


10. How we keep personal data secure

We use a combination of technical, organisational and physical measures to protect personal data.

These measures include:

  • restricted access based on job role
  • secure authentication and password controls
  • multi factor authentication where supported
  • encryption of data in transit and at rest where possible
  • audit logs and monitoring of system access
  • staff training in confidentiality and information security
  • clear policies and training for handling personal information
  • secure storage of paper records
  • controlled physical access to buildings and offices
  • due diligence and security checks on relevant third party providers15. How long we keep personal data

We only keep personal data for as long as necessary. For more information about how long we keep your data, please ask us for a copy of our retention schedule.


11. Your data protection rights

Under UK GDPR you have several rights regarding your personal data.

These include the right to:

  • access personal data we hold about you
  • request correction of inaccurate or incomplete information
  • request deletion of your data in certain circumstances
  • request restriction of how your data is processed
  • object to certain types of processing, where applicable
  • receive your data in a portable format, where applicable
  • challenge decisions based solely on automated processing, where applicable
  • withdraw consent, where we rely on it

These rights are subject to certain legal limitations. Please contact us via our Internal Data Protection Lead on dataprotection@thermoteknix.com to exercise your rights.


12. Complaints

If you have concerns about how your personal data has been handled, you should first raise this with Thermoteknix using the contact details provided above.

We will review your concern and aim to acknowledge your complaint within 30 days and respond as soon as reasonably possible. Where appropriate we may seek advice from our data protection specialist to assist in resolving the issue.

If you remain dissatisfied, you have the right to raise a complaint with the Information Commissioner’s Office, the UK’s data protection regulator.


13. Updates to this notice

This notice was last updated on: 18 August 2026. We may update this notice from time to time to reflect changes in law, technology or organisational practices.

Where significant changes occur, we will notify staff and publish the updated notice internally.



Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.